CVE-2020-8744
Published on: 11/12/2020 12:00:00 AM UTC
Last Modified on: 10/19/2022 01:29:00 PM UTC
Certain versions of Converged Security And Management Engine from Intel contain the following vulnerability:
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2020-8744 has been assigned by
s[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 4.6 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Intel SA-00391 Intel TXE Vulnerabilities in NetApp Products | NetApp Product Security | Third Party Advisory security.netapp.com text/html |
![]() |
Intel SA-00391 CSME Vulnerabilities in NetApp Products | NetApp Product Security | Third Party Advisory security.netapp.com text/html |
![]() |
cert-portal.siemens.com application/pdf |
![]() | |
INTEL-SA-00391 | Vendor Advisory www.intel.com text/html |
![]() |
Intel SA-00391 SPS Vulnerabilities in NetApp Products | NetApp Product Security | Third Party Advisory security.netapp.com text/html |
![]() |
Related QID Numbers
- 590675 Siemens SIMATIC S7-1500 Multiple Vulnerabilities (ICSA-21-131-15)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Intel | Converged Security And Management Engine | All | All | All | All |
Application | Intel | Converged Security And Management Engine | All | All | All | All |
Application | Intel | Server Platform Services | All | All | All | All |
Application | Intel | Server Platform Services | All | All | All | All |
Operating System | Intel | Trusted Execution Engine | All | All | All | All |
Operating System | Intel | Trusted Execution Engine | All | All | All | All |
Hardware
| Siemens | Simatic S7-1500 | - | All | All | All |
Operating System | Siemens | Simatic S7-1500 Firmware | - | All | All | All |
Hardware
| Siemens | Simatic S7-1518-4 Pn/dp Mfp | - | All | All | All |
Operating System | Siemens | Simatic S7-1518-4 Pn/dp Mfp Firmware | - | All | All | All |
Hardware
| Siemens | Simatic S7-1518f-4 Pn/dp Mfp | - | All | All | All |
Operating System | Siemens | Simatic S7-1518f-4 Pn/dp Mfp Firmware | - | All | All | All |
- cpe:2.3:a:intel:converged_security_and_management_engine:*:*:*:*:*:*:*:*:
- cpe:2.3:a:intel:converged_security_and_management_engine:*:*:*:*:*:*:*:*:
- cpe:2.3:a:intel:server_platform_services:*:*:*:*:*:*:*:*:
- cpe:2.3:a:intel:server_platform_services:*:*:*:*:*:*:*:*:
- cpe:2.3:o:intel:trusted_execution_engine:*:*:*:*:*:*:*:*:
- cpe:2.3:o:intel:trusted_execution_engine:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-1500_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-1518-4_pn\/dp_mfp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-1518-4_pn\/dp_mfp_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-1518f-4_pn\/dp_mfp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-1518f-4_pn\/dp_mfp_firmware:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|